mcpbeat Sign in

Malwarebytes MCP Server

by malwarebytes Your server? Claim it
answering

Malwarebytes is answering right now. Last checked 12 min ago. It exposes 6 tools.

Uptime history 52 days of history · worst day 99%
52 days agonow
100.0%
Uptime 24h
91 of 91 checks
6
Tools
read from the server
460 ms
Response time
average over 24h
open, no key
Access
streamable-http

Malwarebytes missed one check this week

Everything else answered, so this is steady rather than shaky. We check every 15 minutes, which is how a one-off gets told apart from the start of a pattern, and how you hear about the next one within the hour instead of from your users.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 12 min ago.

run in your terminal
claude mcp add mcp --transport http https://scamguard.malwarebytes.com/claude/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp": {
      "url": "https://scamguard.malwarebytes.com/claude/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.mcp]
url = "https://scamguard.malwarebytes.com/claude/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "mcp": {
      "url": "https://scamguard.malwarebytes.com/claude/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "mcp": {
      "url": "https://scamguard.malwarebytes.com/claude/mcp"
    }
  }
}

Available tools 6

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

reputation
reputation-check_email
Use this when you need to check if an email address is associated with phishing, scams, or malicious activity. Checks the email domain against threat intelligence database. Returns one of: - malicious: Confirmed phishing or malicious email domain - suspicious: Potentially dangerous email domain - safe: Verified legitimate email domain - unknown: No threat intelligence available Cross-tool workflow: - If the email contains URLs, consider scanning them with reputation-check_link. - If the email contains phone numbers, consider scanning them with reputation-check_phone. - For unknown or suspicious verdicts, consider using reputation-whois to check domain registration details (age, registrar, abuse contact). Do not use this for email validation, mailbox verification, or general email lookup services.
reputation-check_link
Use this when you need to check if a link or URL is safe, suspicious, or malicious. Provides reputation verdict based on threat intelligence database. Returns one of: - malicious: Confirmed harmful link - suspicious: Potentially dangerous link - safe: Verified safe link - unknown: No threat intelligence available Cross-tool workflow: - For unknown or suspicious verdicts, consider using reputation-whois to check domain registration details (age, registrar, abuse contact). - If the URL redirects to a different domain, consider scanning the destination URL separately. - If the URL came from an email or text message, consider checking the sender with reputation-check_email or reputation-check_phone. Do not use this for general web searches, content fetching, or webpage analysis.
reputation-check_phone
Use this when you need to check if a phone number is associated with scams or suspicious activity. Provides reputation verdict and additional phone information. Returns one of: - malicious: Confirmed scam or spam phone number - suspicious: Potentially dangerous number - safe: Verified legitimate number - unknown: No threat intelligence available Also provides optional details like carrier, location, and phone type when available. Cross-tool workflow: - If the caller provided links, consider scanning them with reputation-check_link. - If the caller provided email addresses, consider scanning them with reputation-check_email. Do not use this for phone number lookups, caller ID services, or general phone directory searches.
reputation-report
Use this when a user wants to report a suspicious link, email address, or phone number. Submits the indicator to the threat intelligence system for analysis. Only use when explicitly requested by the user. Do not use this to automatically report every checked item.
reputation-scan_all
Use this when you need to check multiple links, emails, or phone numbers at once. Scans all indicators concurrently and returns a unified result. Each indicator needs: - type: 'url', 'email', or 'phone' - value: the URL, email address, or phone number (E.164 format for phones) Returns a summary with counts per verdict and individual results for each indicator. Prefer this over individual scan tools when 3 or more indicators are present. Maximum 10 indicators per request. Cross-tool workflow: - For unknown URL or email verdicts, consider using reputation-whois on the associated domains for additional registration context and abuse contact information.
reputation-whois
Use this when you need to look up domain registration information to verify legitimacy or identify suspicious patterns. Provides WHOIS/RDAP data including registrar, registration dates, name servers, and abuse contacts. Particularly useful for identifying newly registered domains (common in phishing and scams). Returns the registrar's abuse contact email when available, which can be used for filing complaints about fraudulent domains. Cross-tool workflow: - Consider using reputation-check_link to check the domain's threat reputation alongside WHOIS registration data. Do not use this for general domain availability checks or bulk domain searches.

Endpoints

URLTransportStateLatencyChecked
https://scamguard.malwarebytes.com/claude/mcp streamable-http answering 388 ms 12 min ago

Alternatives to Malwarebytes

same job, measured the same way
Bytes to MiB
by sadri-dridi

Bytes to MiB

31 tools answering
Megabytes to gigabytes
by sadri-dridi

Megabytes to gigabytes

31 tools answering
Kilobytes to megabytes
by sadri-dridi

Kilobytes to megabytes

31 tools answering
Bytes to KiB
by sadri-dridi

Bytes to KiB

31 tools answering
DEX magic shape, bytes discarded
by sadri-dridi

DEX magic shape, bytes discarded

31 tools answering
Mach-O magic band, bytes discarded
by sadri-dridi

Mach-O magic band, bytes discarded

31 tools answering
I
Crypto Bytes
by mickymultani

Crypto Bytes MCP Server

66 installs/wk local only
pcap magic endian, bytes discarded
by sadri-dridi

pcap magic endian, bytes discarded

31 tools answering

Malwarebytes — questions

Answers built from our own checks of this server.

What can Malwarebytes do?
It exposes 6 tools, read directly from the server on our last check. Among them: reputation-check_email, reputation-check_link, reputation-check_phone, reputation-report, reputation-scan_all, reputation-whois. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Malwarebytes working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 460 ms. The bar chart above shows every period we have measured.
How do I connect Malwarebytes?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Malwarebytes need an API key?
No. Malwarebytes completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 6 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Malwarebytes?
It answers our handshake in 460 ms on average, which is faster than 34% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.